Once the ppolicy overlay is enabled all users will become subject to the default policy. You have 2 choices:

1.Make the default policy accommodate your less restrictive use case and apply a more restrictive policy to the users that need it.

2.Leave the default policy the more restrictive case, create a less restrictive policy for your “exception” use case and apply the less restrictive
policy to users that need it.

The method you choose will be driven by which use case is the “rule” and which use case is the “exception”. In either case you apply distinct policies where
needed by supplying the DN of the policy in the pwdPolicySubentry attribute of the user.